Mexico reportedly breached via Claude exploitation Numerous Mexican government agencies have been compromised in a month-long attack campaign beginning in December that weaponized Anthropic's Claude large language model, resulting in the theft of 150 GB of data, according to Cybernews.
The issue arises because Google Cloud API keys, once used solely for extending functionality like embedding maps or tracking usage, now also authenticate users to the Gemini AI assistant.
The threat actor claims to have accessed servers containing information on approximately 400,000 individuals, including names, addresses, email addresses, and phone numbers.
The Federal Trade Commission has announced that it will not enforce Children's Online Privacy Protection Rule penalties against companies that properly use age verification technologies to collect and process personal data, reports The Record, a news site by cybersecurity firm Recorded Future.
Cybernews reports that Dungeon Crusher, a widely played RPG game, had its players' partial purchase data and in-game chats inadvertently leaked by a misconfigured Elasticsearch instance.
More than 3.4 million individuals were reported by health insurance tech provider TriZetto Provider Solutions, a subsidiary of Cognizant, to have had their sensitive data stolen following a 2024 breach, according to The Record, a news site by cybersecurity firm Recorded Future.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.